Re: [pfSense] Captive Portal questions - Interstitial page

2014-02-28 Thread Ryan Coleman
We’re not doing a login page - it’s a simple thanks for coming, here are some basic rules and see our specials. Think of it like a McDonald’s or chain coffee shop page. I can “bless” access through the CP - in fact I’m already doing that for the CSS, images and javascript files. On Feb 28, 201

Re: [pfSense] Captive Portal questions - Interstitial page

2014-02-28 Thread Chris L
I don’t think so. Your remote system will not have access to the things pfSense needs to add the captive portal bypass entries to ipfw. Namely the MAC address associated with the IP Address. A RADIUS Server could be remote. On Feb 27, 2014, at 8:17 AM, Ryan Coleman wrote: > Can I have the i

[pfSense] Blocking based on MAC

2014-02-28 Thread Ryan Coleman
I just checked google and the “best” solution from a few versions ago is to reserve the MAC IP to something out of range. I’d like to find a “simple” way to do that for my customer. Is there a better way to block a MAC? — Ryan ___ List mailing list L

Re: [pfSense] Freezing Entering NAT Rules

2014-02-28 Thread James Caldwell
Turned out to be bad/dieing hardware. Replaced the firewall with a new Dell server and everything is back to normal. Thanks, James From: list-boun...@lists.pfsense.org [mailto:list-boun...@lists.pfsense.org] On Behalf Of Chris Buechler Sent: February-23-14 6:16 PM To: pfSense support and discu

Re: [pfSense] Are WAN rules needed for ISAKMP and ESP?

2014-02-28 Thread Ryan Coleman
I believe so. I have two ports opened under Rules for my IPSEC configuration. On Feb 28, 2014, at 3:27 PM, Brian Candler wrote: > Is it necessary to add explicit rules to allow inbound ISAKMP (UDP 500) and > ESP (IP protocol 50) on the WAN interface? > > I had a problem with pfsense 2.0.1 fai

[pfSense] Are WAN rules needed for ISAKMP and ESP?

2014-02-28 Thread Brian Candler
Is it necessary to add explicit rules to allow inbound ISAKMP (UDP 500) and ESP (IP protocol 50) on the WAN interface? I had a problem with pfsense 2.0.1 failing to accept sessions initiated by a Cisco ASA5505. tcpdump showed the ASA was sending ISAKMP phase 1 and pfsense was not replying. I a

Re: [pfSense] verizon USB data modem

2014-02-28 Thread Vick Khera
On Thu, Feb 27, 2014 at 10:29 PM, Oliver Hansen wrote: > Hi Vick, I have used the Pantech UML290 on Verizon. It looks like VZW > still sells the UML290 on their web site but I have not had experience yet > with the UML295. I may get ahold of one sometime in the near future so if I > do I'll let yo

[pfSense] How to track these kind of things ?

2014-02-28 Thread Nenhum_de_Nos
hail, I just got pfSense 2.1 running on an IBM machine using igb cards, and got all crazy things from them. I then found https://forum.pfsense.org/index.php/topic,66908.msg367991.html#msg367991 and https://github.com/pfsense/pfsense/commit/f3a4601c85c4de78caa4f12fefd64067fd83dbe8, and it looks

[pfSense] can not block skype with snort and confusion on squid custom rule.

2014-02-28 Thread Muhammad Yousuf Khan
i am trying to block skype logging with the signature number 5999 and 6001 as describe in few howtos. i added all p2p rules for skype. but the main signaure with sid 6001 is missing. i can not see that signature in the list. however i can see 5999 and few others related to skype which are not doin

Re: [pfSense] no internet access on vlan

2014-02-28 Thread J. Echter
unbelievable, but i've overseen the following: php: rc.initial.setlanip: The command '/sbin/ifconfig 'lagg0_vlan3' inet delete' returned exit code '1', the output was 'ifconfig: ioctl (SIOCDIFADDR): Can't assign requested address' Am 28.